# CLI: what does cExtendedCmdSearch mean?

**URL:** <https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636>\
**Category:** Other Northbound Interfaces\
**Created:** [February 22, 2024, 5:24am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636 "2024-02-22T05:24:26Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 22, 2024, 5:24am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/1 "2024-02-22T05:24:27Z")

</div>

Hi tail-f support,  
In confd.conf, cExtendedCmdSearch is explained as below:

> Extend the available submode commands to all commands in  
> parent (and grand-parent) modes. These commands are not  
> visible during completion but will be executed if entered.  
> If set to “false” then only commands for entering other  
> submodes are available in parent and grand-parent modes,  
> if set to “true” all commands in parent and grand-parent  
> modes are available.

What does all commands in parent modes mean? Does it mean the following commands at top level:

```auto
admin@E-5CG23641SM>
Possible completions:
  clear - Clear parameter
  compare - Compare running configuration to another configuration or a file
  configure - Manipulate software configuration information
  describe - Display transparent command information
  exit - Exit the management session
  file - Perform file operations
  help - Provide help information
  id - Show user id information
  leaf-prompting - Automatically query for leaf values
  monitor - Real-time debugging
  ping - Ping a host
  quit - Exit the management session
  request - Make system-level requests
  script - Script actions
  set - Set CLI properties
  set-path - Set relative show path
  show - Show information about the system
  source - File to source
  top - Exit to top level and optionally run command
  traceroute - Trace the route to a remote host
  up - Exit one level of configuration

```

Would you please give an example of this parameter?  
BRs  
Michael

---

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 22, 2024, 6:59am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/2 "2024-02-22T06:59:56Z")

</div>

Need your help on the sentence below:

```auto
If set to 'false' then only commands for entering other submodes are available in parent and grand-parent modes

```

Does this mean that it have the same effect as the parameter topLevelCmdsInSubMode?

And also it does not take effect when setting the following configuration which is to prevent non-local commands from being executed:

```auto
<cSuppressCmdSearch>false</cSuppressCmdSearch>

```

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![cohult](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/cohult/32/221_2.png) [@cohult](https://dmap-community.ductus.global/u/cohult)\
**Post date:** [February 26, 2024, 4:11pm UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/3 "2024-02-26T16:11:42Z")

</div>

Using the $CONFD\_DIR/examples.confd/intro/1-2-3-start-query-model example:  
`(config)# dhcp shared-networks shared-network sn1`  
From this mode::  
`(config-shared-network-sn1)# dhcp shared-networks shared-network sn2`  
and so on:

```plaintext
(config-shared-network-sn2)# dhcp shared-networks shared-network sn3
(config-shared-network-sn3)# dhcp shared-networks shared-network sn4 subnets subnet 1.1.1.1 255.255.255.255
(config-subnet-1.1.1.1/255.255.255.255)# dhcp shared-networks shared-network sn5 subnets subnet 2.2.2.2 255.255.255.255
(config-subnet-2.2.2.2/255.255.255.255)#

```

This is a “short-cut” to execute commands that are not in the current mode.

---

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 27, 2024, 2:19am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/4 "2024-02-27T02:19:24Z")

</div>

Hi cohult,  
Thank you very much. I have tried your suggestion. It works.  
So only the commands defined in yang modules are controlled by the 2 parameters cExtendCmdSearch and cSuppressCmdSearch? The commands defined in clispec file commands-c.cli and other buillt-in comands such as abort, clear and so on are not impacted by them?  
BRs  
Michael

---

<div class="post-metadata">

**Author:** ![cohult](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/cohult/32/221_2.png) [@cohult](https://dmap-community.ductus.global/u/cohult)\
**Post date:** [February 27, 2024, 7:23am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/5 "2024-02-27T07:23:52Z")

</div>

Hi @hzpfly

> [@hzpfly](#):
>
> The commands defined in clispec file commands-c.cli and other buillt-in comands such as abort, clear and so on are not impacted by them?

They are reachable from submodes too.

---

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 27, 2024, 8:37am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/6 "2024-02-27T08:37:45Z")

</div>

Yes, but these commands defined in clispec file and other built-in commands cannot be disabled in submodes by these 2 parameters. Right?

---

<div class="post-metadata">

**Author:** ![cohult](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/cohult/32/221_2.png) [@cohult](https://dmap-community.ductus.global/u/cohult)\
**Post date:** [February 27, 2024, 9:14am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/7 "2024-02-27T09:14:31Z")

</div>

I believe you need to provide an example to explain what you want to do or not do.

---

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 27, 2024, 9:26am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/8 "2024-02-27T09:26:18Z")

</div>

Here is an example:  
I add the following lines in confd.conf:

```auto
<cli>                                           
  <cExtendedCmdSearch>false</cExtendedCmdSearch>
  <cSuppressCmdSearch>true</cSuppressCmdSearch> 
  <cModeExitFormat>exit</cModeExitFormat>       
</cli>                                          

```

I think the top level commands such as do, clear and so on is not available in submode. But it is not the case:

```auto
E-5CG23641SM(config)# dhcp shared-networks shared-network sn5
E-5CG23641SM(config-shared-network-sn5)#
Possible completions:
  subnets
  ---
  commit Commit current set of changes
  describe Display transparent command information
  exit Exit from current mode
  help Provide help information
  no Negate a command or set its defaults
  pwd Display current mode path
  top Exit to top level and optionally run command
E-5CG23641SM(config-shared-network-sn5)# do show running-config dhcp
dhcp shared-networks shared-network sn1
exit

```

BRs  
Michael

---

<div class="post-metadata">

**Author:** ![cohult](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/cohult/32/221_2.png) [@cohult](https://dmap-community.ductus.global/u/cohult)\
**Post date:** [February 27, 2024, 12:23pm UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/9 "2024-02-27T12:23:12Z")

</div>

You need to use NACM to disallow the execution of a specific command (built-in or clispec command) in a submode.  
Set modeInfoInAAA to true in your confd.conf

```xml
<cli>                                           
  <modeInfoInAAA>true</modeInfoInAAA>     
</cli>  

```

Then, add a cmd rule to the aaa config, e.g., in aaa\_init.xml. Something like:

```xml
    <cmdrule xmlns="http://tail-f.com/yang/acm">
      <name>no-do-cmd-in-config-submode</name>
      <context>cli</context>
      <command>configure ^config-.*$ do</command>   
      <access-operations>read exec</access-operations>
      <action>deny</action>
    </cmdrule>

```

---

<div class="post-metadata">

**Author:** ![hzpfly](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@hzpfly](https://dmap-community.ductus.global/u/hzpfly)\
**Post date:** [February 28, 2024, 8:31am UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/10 "2024-02-28T08:31:57Z")

</div>

Thank you very much @cohult. Now I can answer my questions now:

> What does all commands in parent modes mean? Does it mean the following commands at top level

My answer: if cExtendedCmdSearch is true, in submode, all commands in parent modes are also can be executed. All commands here is the commands defined in user defined Yang modules, not the built-in or clispec defined commands.

> Does this mean that it have the same effect as the parameter topLevelCmdsInSubMode?

My answer: No, they are different. topLevelCmdsInSubMode is only for built-in or clispec defined commands.

> So only the commands defined in yang modules are controlled by the 2 parameters cExtendCmdSearch and cSuppressCmdSearch? The commands defined in clispec file commands-c.cli and other buillt-in comands such as abort, clear and so on are not impacted by them?

My answer: Yes. And all commands can be authorized by nacm rules.

@cohult, do you think my answer is right or not?

---

<div class="post-metadata">

**Author:** ![cohult](https://yyz2.discourse-cdn.com/flex010/user_avatar/dmap-community.ductus.global/cohult/32/221_2.png) [@cohult](https://dmap-community.ductus.global/u/cohult)\
**Post date:** [March 1, 2024, 3:45pm UTC](https://dmap-community.ductus.global/t/cli-what-does-cextendedcmdsearch-mean/4636/11 "2024-03-01T15:45:05Z")

</div>

@hzpfly Seems correct
